CVE-2026-92842

NameCVE-2026-92842
DescriptionThe convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itself. The filter constructors duplicate the value with pestrdup(), which stops at the first NUL byte, while keeping the original length. When the filter later emits a line break it copies the recorded length out of the truncated allocation, reading past its end and placing adjacent heap bytes into the filter output.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6514-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php8.2 (PTS)bookworm8.2.32-1~deb12u1vulnerable
bookworm (security)8.2.33-1~deb12u1vulnerable
php8.4 (PTS)trixie8.4.24-1~deb13u1vulnerable
trixie (security)8.4.26-1~deb13u1fixed
forky, sid8.4.24-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php8.2source(unstable)(unfixed)
php8.4sourcetrixie8.4.26-1~deb13u1DSA-6514-1
php8.4source(unstable)(unfixed)

Notes

https://github.com/php/php-src/security/advisories/GHSA-88hq-2827-7pg6
https://github.com/php/php-src/blob/php-8.4.26/NEWS

Search for package or bug name: Reporting problems